Malware

Generic.DataStealer.1.8112626B malicious file

Malware Removal

The Generic.DataStealer.1.8112626B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.DataStealer.1.8112626B virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

How to determine Generic.DataStealer.1.8112626B?


File Info:

crc32: 12EFF33F
md5: 13c188c2752a30922c4efcda13d98c3a
name: 13C188C2752A30922C4EFCDA13D98C3A.mlw
sha1: 2500f76e04983393ed5863effa7bdcc0f93b4403
sha256: bb8092fb1fe474f0b7ac56df60cf32c9935a9c84c492998a6fdc54a682ab283d
sha512: ccaa46d39e75139af1845cc7b40e9a60cb5a75cb28fb91663985c6a537e6ee29b6fdc8798105ce3430fe83273347c92997c365e3c6c5b5e5de26b351f26be958
ssdeep: 1536:3klFY0t3qT81rnsthfbmnZl1I6dV52TE7KyTOn7oTv1FkzbkME/gS/GI+9yvnrV:U/9tHn2KnNfs0OnL9E/5GtsrV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.DataStealer.1.8112626B also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.4118
CynetMalicious (score: 100)
CAT-QuickHealTrojanpws.Tepfer.20314
ALYacGeneric.DataStealer.1.8112626B
CylanceUnsafe
SangforWin.Trojan.Fareit-403
CrowdStrikewin/malicious_confidence_100% (W)
K7GWPassword-Stealer ( 004d62531 )
Cybereasonmalicious.2752a3
BaiduWin32.Trojan-PSW.Fareit.a
SymantecDownloader.Ponik!gm
ESET-NOD32a variant of Win32/PSW.Fareit.D
APEXMalicious
AvastSf:Crypt-AQ [Trj]
ClamAVWin.Trojan.PonyStealer-9831667-0
KasperskyTrojan-PSW.Win32.Tepfer.gen
BitDefenderGeneric.DataStealer.1.8112626B
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotBackdoor.Win32.Pony.Gen.A
SUPERAntiSpywareHack.Tool/Gen-Spyware
MicroWorld-eScanGeneric.DataStealer.1.8112626B
TencentTrojan.Win32.Tepfer.a
Ad-AwareGeneric.DataStealer.1.8112626B
SophosML/PE-A + Troj/DwnLdr-MJA
ComodoTrojWare.Win32.PWS.Fareit.GS@5t8zib
BitDefenderThetaGen:NN.ZexaF.34684.hqW@aSewYrf
VIPRETrojan.Win32.Fareit.j (fs)
TrendMicroTSPY_FAREIT.SMY
McAfee-GW-EditionBehavesLike.Win32.Backdoor.ch
FireEyeGeneric.mg.13c188c2752a3092
EmsisoftGeneric.DataStealer.1.8112626B (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/PSW.Tepfer.cdzb
AviraTR/Kryptik.avp.8
eGambitUnsafe.AI_Score_100%
MicrosoftPWS:Win32/Fareit
GridinsoftTrojan.Win32.Fareit.vl!i
GDataWin32.Trojan-Stealer.Fareit.O
AhnLab-V3Trojan/Win32.Tepfer.R142848
Acronissuspicious
McAfeeTrojan-FEOF!13C188C2752A
MAXmalware (ai score=83)
VBA32SScope.Malware-Cryptor.Ponik
MalwarebytesSpyware.Pony
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_FAREIT.SMY
RisingStealer.Fareit!8.170 (TFE:dGZlOgJmjdeFOpWuOA)
YandexTrojan.GenAsa!n7oQnOSRBEM
IkarusTrojan.Crypt
FortinetW32/Fareit.G!tr
AVGSf:Crypt-AQ [Trj]

How to remove Generic.DataStealer.1.8112626B?

Generic.DataStealer.1.8112626B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment